How it works Pricing Guides FAQ Trust Login Start free

RFI Hawk

Trust Center

Operated by Salian Defense
Last updated 2026-09-02

RFI Hawk is built by a defense-industry team for defense and federal contractors. This page states what is actually in place today, what is not, and what is on the roadmap. It is written to be checked, not to impress. We do not publish low-level implementation details, software bills of materials, or named vendor relationships in public; detailed documentation is shared with prospects and customers under NDA on request.

What you may upload and what you must not

RFI Hawk is a commercial cloud service. Do not upload classified information, ITAR or EAR export-controlled technical data. RFI Hawk has not been independently assessed or authorized for Controlled Unclassified Information (CUI). Proprietary company information and Federal Contract Information (FCI) are within scope of our published security controls. You remain responsible for determining the classification of what you upload.

The same rule appears beside every file upload control in the product, and section 5.4 of the Terms of Service makes it a condition of use.

Encryption

Tenant isolation

Customer data is logically isolated. Every request for a user-owned resource (a document, a proposal, a company profile, a saved search) is checked against the requester's ownership before it is returned, so one account cannot read or modify another account's data by guessing identifiers. This is object-level access control, sometimes called IDOR protection. It is not per-tenant databases or per-tenant infrastructure: all customers share one application and one database, and uploaded files are stored in per-user folders.

Authentication and access

AI processing

Data retention and deletion

Backups

Backups are taken by the operator; automated backup verification is an open POA&M item. Our contingency plan sets a 24-hour recovery point objective and a 4-hour recovery time objective as targets. A full recovery drill has not yet been recorded, so treat those figures as targets rather than demonstrated results.

Logging and monitoring

Dependencies

Third-party packages are version-pinned. Known vulnerabilities are surfaced two ways: automated dependency alerts from our source code host, and a vulnerability audit that runs in continuous integration on every change. Fixes are floored in the pinned requirements as they ship.

Payments

All payment processing is performed by Stripe, a PCI DSS Level 1 service provider. Card numbers are entered directly with Stripe and never touch RFI Hawk infrastructure; we store only the processor-issued customer identifier and subscription status.

Hosting

The application and database run on US-based cloud infrastructure provided by a commercial hosting platform. It is not a government cloud, and it does not carry a FedRAMP authorization.

Compliance posture

What we do not hold. RFI Hawk does not hold a FedRAMP authorization, a SOC 2 attestation, or an ISO 27001 certification, and we do not claim any certification we have not earned. RFI Hawk does not hold a FedRAMP authorization. FedRAMP is a post-GA roadmap item.

NIST SP 800-53. We map our controls against the NIST SP 800-53 Rev. 5 Moderate baseline. That mapping is offered as alignment, not authorization, and it is not a claim of authorization. The following control families have controls implemented today with supporting evidence:

Other families (for example Configuration Management, Contingency Planning, and Incident Response) are partially implemented or documented with open items. The control-by-control register and the plan of action and milestones are maintained internally and shared with qualified prospects and customers under NDA.

NIST SP 800-171 and CMMC. The CMMC suite inside the product is built around the NIST SP 800-171 requirement set so that customers can track their own controls, and its own controls follow that requirement set. That alignment describes the product's content. It is not an independent assessment of RFI Hawk against NIST SP 800-171, RFI Hawk is not a C3PAO, and RFI Hawk has not been assessed or authorized for CUI.

Roadmap. Pursuing a FedRAMP authorization on a U.S. government cloud, where the underlying cryptographic modules are FIPS 140-2 validated, is a planned milestone after general availability. It is not a status we hold today, and nothing on this page should be read as FIPS validation of the current environment.

Subprocessors

We rely on a small set of service providers, in these categories:

A current named list is available on request to security@saliandefense.com. We do not use advertising networks, tracking pixels, or data brokers.

Incident response

We maintain a written incident response plan covering severity classification, containment, eradication, recovery, and post-incident review. Customers whose data is affected by a confirmed incident are notified without undue delay, and within 72 hours of confirmation, with what happened, what data was affected, what we have done, and what they should do. Regulatory notifications are made where the law requires them.

Vulnerability disclosure

If you believe you have found a security vulnerability in RFI Hawk, please disclose it responsibly to security@saliandefense.com. Our disclosure contact is also published at /.well-known/security.txt. Encrypted reports are welcome; PGP details are available on request.

We acknowledge legitimate reports within two business days and work in good faith with researchers who follow responsible-disclosure norms.

Last updated 2026-09-02. Operated by Salian Defense. Questions: security@saliandefense.com.